Skip to content

Moroccan Medical Provider Distamed Allegedly Breached, Patient Records and 13 Years of Company Archive Claimed

Breach Report Morocco flagMorocco Healthcare / Medical Devices Data Leaked

Moroccan Medical Provider Distamed Allegedly Breached, Patient Records and 13 Years of Company Archive Claimed

A threat actor posting as anisanas2 claims to have extracted the full database of Distamed Morocco, a supplier of medical devices and healthcare solutions to hospitals, clinics, and practitioners, with a stated focus on cardiology, pulmonology, neurology, sleep diagnostics, rehabilitation, and medical imaging. The post claims the material includes the complete client list, patient records, internal files, billing documents, invoices, and document scans, alongside the full company archive dating to 2013. The actor further asserts the data covers the company's dealings with government bodies, including Moroccan military and public hospitals. Named fields include first and last name, phone number, address, age, date of visit, and CIN national identity numbers. No record count or price is stated. The claim is unverified.

RecordsNot stated
RangeBack to 2013
CountryMorocco flagMorocco
Actoranisanas2

Post details

TargetDistamed Morocco
CountryMorocco flagMorocco
SectorHealthcare / Medical devices
ListingReply or upgrade to unlock
RecordsNot stated
DataPatient, client, billing, archive
Observed
Actoranisanas2

!Allegedly included

  • Patient records
  • Full names
  • CIN national ID numbers
  • Phone numbers
  • Home addresses
  • Age
  • Date of visit
  • Full client list
  • Billing documents
  • Invoices
  • Document scans
  • Internal company files
  • Government contract dealings
  • Military hospital records

Screenshot

Potential impact

Health data sits in a category of its own because it cannot be reissued, revoked, or meaningfully mitigated after publication. The named fields alone would be serious, since a CIN pairs with name, address, and phone to form the basis of Moroccan identity verification and underpins access to banking and government services. What raises this further is that the provider's specialisms are themselves disclosive. A patient record held by a supplier concentrated in cardiology, pulmonology, neurology, and sleep diagnostics implies a clinical condition even where no diagnosis field exists, and a date of visit narrows that inference to a point in time. Individuals do not get to opt out of that association once it is public, and the consequences reach into employment, insurance, and family circumstances. The claimed 13-year archive widens the affected group well beyond current patients to anyone who passed through since 2013. The assertion that the material covers military and public hospital dealings introduces a separate dimension: procurement records, equipment inventories, and facility documentation for military medical infrastructure would carry national security relevance independent of the patient data, and would be of interest to parties with no commercial motive at all. The absence of any stated record count means the scale of exposure cannot be assessed from the post. The claim is unverified.

iStatus

Unverified

The post carries no sample data, no record count, and no file listing, offering only a field description behind a reply-or-upgrade gate. That is notably less substantiation than most listings of comparable claimed scope, and the breadth of what is asserted, spanning patient records, corporate archives, and government contracts, is not matched by evidence in the post itself. The account is established on the forum with a moderate history and elevated standing, and promotes external contact channels. The opening line suggests a return to activity after a period of absence. None of the claims have been independently corroborated. The claim is unverified and Distamed has not publicly addressed it.

Want everything on this breach? Paid subscribers get the full claim details and more. Check out the threat feed, then after subscribing, search there for this alert. View pricing →

DARK WEB INFORMER - THREAT INTELLIGENCE

Latest